Search CVE reports


Toggle filters

871 – 880 of 34514 results

Status is adjusted based on your filters.


CVE-2026-5438

Medium priority
Needs evaluation

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on...

1 affected package

orthanc

Package 24.04 LTS
orthanc Needs evaluation
Show less packages

CVE-2026-5437

Medium priority
Needs evaluation

An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although...

1 affected package

orthanc

Package 24.04 LTS
orthanc Needs evaluation
Show less packages

CVE-2025-62718

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-4660

Medium priority
Needs evaluation

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This...

1 affected package

golang-github-hashicorp-go-getter

Package 24.04 LTS
golang-github-hashicorp-go-getter Needs evaluation
Show less packages

CVE-2026-34179

Medium priority
Vulnerable

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS...

2 affected packages

lxd, incus

Package 24.04 LTS
lxd Not in release
incus Vulnerable
Show less packages

CVE-2026-34178

Medium priority
Vulnerable

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same...

2 affected packages

lxd, incus

Package 24.04 LTS
lxd Not in release
incus Vulnerable
Show less packages

CVE-2026-34177

Medium priority
Vulnerable

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under...

2 affected packages

lxd, incus

Package 24.04 LTS
lxd Not in release
incus Vulnerable
Show less packages

CVE-2026-34757

Medium priority
Needs evaluation

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS,...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS
libpng Not in release
libpng1.6 Needs evaluation
firefox Not affected
thunderbird Not affected
chromium-browser Not affected
Show less packages

CVE-2026-1403

Medium priority

Not in release

[Unknown description]

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2026-5173

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages